An issue was discovered in Commvault before 11.36.60. During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.
Metrics
Affected Vendors & Products
References
History
Wed, 20 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 20 Aug 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Commvault before 11.36.60. During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured. | |
Title | Vulnerability in Initial Administrator Login Process | |
Weaknesses | CWE-257 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-08-20T03:22:08.764Z
Updated: 2025-08-21T03:55:09.241Z
Reserved: 2025-08-19T18:25:57.338Z
Link: CVE-2025-57789

Updated: 2025-08-20T13:31:13.038Z

Status : Awaiting Analysis
Published: 2025-08-20T04:16:03.847
Modified: 2025-08-20T14:39:07.860
Link: CVE-2025-57789

No data.